Cybersecurity

Business email compromise: how invoice fraud really works

Business email compromise: an invoice thread with the bank details quietly swapped

The email looks completely normal. It's in a thread you recognise, from a supplier you've paid a dozen times before, mentioning the same job you both discussed last week. The only thing that's changed is eight digits: a sort code and account number, swapped for new ones “due to a change of bank.” Someone pays it. Three weeks later the real supplier rings asking why their invoice is still outstanding, and by then the money is long gone.

That's business email compromise, and unlike most cybercrime it doesn't need malware, a dodgy link, or a single technical failure on your side. It needs one person, one moment of trust, and no habit of checking. Here's how it actually works, what UK Finance's own numbers say it costs, why your bank might not give the money back, and the one check that stops most of it dead.

What business email compromise actually is

Business email compromise, usually shortened to BEC, is a scam built around a real conversation rather than a fake one. The criminal doesn't need you to click anything. They need access to, or a convincing copy of, a genuine email thread between your business and someone you already pay: a supplier, a contractor, sometimes your own landlord or accountant. Once they're in that thread, or close enough to it, they wait for the natural moment an invoice or payment would come up, and they insert themselves at exactly that point.

There's no ransom note, no locked files, nothing that announces itself. The whole scam succeeds by looking completely ordinary, which is exactly why it works on careful people just as often as careless ones.

The invoice trick, step by step

Most versions follow the same shape. A criminal gets visibility into an existing email relationship, either by compromising one side's mailbox directly, usually through a reused or phished password with no two-factor authentication in the way, or by registering a lookalike domain one character off the real one and hoping nobody checks the sender address on a phone screen where it's easy to miss.

From there, they watch. Real invoices go back and forth for weeks, sometimes months, while the criminal learns the tone, the amounts, who signs off what. Then, timed to land right before or alongside a genuine invoice, a message arrives: a bank detail update, a new account "for this payment only," sometimes with a plausible reason attached, a bank switch, a merger, an accountant change. The wording matches how your supplier actually writes. The invoice number matches a real job. Everything checks out except the eight digits that decide where the money actually goes.

CEO fraud: the other flavour

A close cousin skips the supplier angle entirely and impersonates someone inside your own business, usually a director or senior manager, emailing someone junior enough to not question it and with the authority to move money. The message is deliberately urgent and deliberately awkward to verify: "I'm in a meeting and can't take calls, need this paid before 3pm, will explain later." The pressure is the point. It's designed to short-circuit exactly the kind of second check that would catch it.

What it actually costs

UK Finance's Annual Fraud Report 2026, covering 2025, recorded £576.4 million lost to authorised push payment fraud across the UK, up 19% on the year before, spread across 248,070 individual cases. Authorised push payment fraud is the technical name for exactly this: a payment the victim genuinely authorised, sent willingly, because they believed the request was real. It's a different legal category from someone stealing your card details, and that distinction matters more than it sounds like it should, because it changes what you're entitled to get back.

Why your bank might not give the money back

Since 7 October 2024, the Payment Systems Regulator has run a mandatory reimbursement scheme covering Faster Payments and retail CHAPS transfers, with a maximum payout of £85,000 per claim. It sounds like a safety net, and for the customers it actually covers, it mostly is. The catch is who's in scope: consumers, micro-enterprises and charities. A micro-enterprise is broadly under 10 staff and under €2 million in turnover or balance sheet. If your business sits above that line, the scheme doesn't apply to you as a matter of right. What you get back is down to your bank's discretion and how fast you flagged it, not a legal guarantee.

Even within the scheme, there's a £100 voluntary excess some banks apply, and the cost is split 50/50 between the bank that sent the payment and the bank that received it, which is part of why banks now push callback verification so hard. It's genuinely in their interest too. Worth an honest five-minute call to your own bank to find out exactly where your business sits against that threshold, rather than assuming either way.

The one habit that stops most of it

Never confirm a bank detail change using contact information that arrived in the same email. Not the phone number in the signature, not a "click to call" link, none of it. Ring the supplier on a number you already had on file, from a previous invoice, your own accounting software, or their website typed in manually, and get a real person to confirm the change out loud. It takes five minutes. It's the single control that ends this scam every time it's actually followed, because the criminal has your supplier's email, or something close to it, but not their phone line.

What NCSC recommends beyond the phone call

The National Cyber Security Centre publishes dedicated guidance on defending against business email compromise, and three of its recommendations are worth adopting as standing policy rather than a one-off reminder.

  • Dual approval above a threshold. No single person, whatever their seniority, should be able to authorise a payment above an agreed amount alone. Pick a number that suits your business and stick to it.
  • Reduce senior staff's public digital footprint. Detailed "meet the team" pages and LinkedIn posts about who's travelling when make a targeted CEO fraud email far more convincing. It's a trade-off against normal marketing, worth thinking about deliberately rather than by accident.
  • Give staff explicit permission to question a request. The junior member of the accounts team is often the one person who can stop this, and only if they know that asking "can I just check this with you by phone first" won't get them in trouble, even if the sender is genuinely their boss.

What to do if you've already paid a fraudulent invoice

Call your bank immediately, using their genuine number from a card or statement, not a number from the fraudulent email, and ask them to attempt a recall on the payment. Faster Payments transfers can sometimes be frozen or clawed back in the first few hours if the receiving bank acts fast, though the odds drop sharply after that window closes. Report it to Action Fraud at reportfraud.police.uk, and separately to NCSC via report.ncsc.gov.uk if a compromised email account was involved rather than just a lookalike domain. Change the password and enable two-factor authentication on any account you suspect was accessed, and check whether other invoices sent from that account in the same window need re-verifying with the real recipients.

Where this overlaps with email authentication

This is the process side of a problem that also has a technical side. Our guide to SPF, DKIM and DMARC covers stopping criminals spoofing your own domain outbound, which protects the people who receive email claiming to be from you. It does nothing, on its own, to protect you from a supplier or customer whose domain isn't locked down the same way, which is exactly why the callback habit matters regardless of how good your own email security is. The two fixes are complementary, not interchangeable, and a business only really covered when both are in place.

The mistakes we see most often

One person with sole authority to move money, no second check required at any amount. Bank detail changes accepted by email with no phone confirmation, because everyone's busy and the invoice looked completely normal. No two-factor authentication on the email accounts that actually send and receive invoices, so a single reused password is the only thing standing between a criminal and weeks of real correspondence to study. And an assumption, usually never actually checked, that "the bank will just refund it if something goes wrong."

Where Alpha IT comes in

We can close off a good part of the technical route in: two-factor authentication on email accounts, SPF, DKIM and DMARC set up properly so criminals can't spoof your own domain, and lookalike-domain monitoring so a near-identical registration doesn't sit there unnoticed for months. What we can't do is sit inside your accounts payable process. The callback habit and the payment threshold are decisions your team has to make and actually keep to, and that's exactly the kind of gap our health check is built to find before it costs you a real invoice.

Frequently asked questions

What's the difference between business email compromise and an ordinary phishing email?+

A phishing email is a stranger casting a wide net, usually with obvious tells: a weird sender address, a generic greeting, a link to a fake login page. Business email compromise is targeted and patient. The criminal has either broken into a real mailbox or built a convincing lookalike of one, read genuine correspondence to learn how your business actually talks and who signs off payments, and then steps into an existing conversation at exactly the right moment. There's no dodgy link to click. The email just asks you to pay an invoice you were already expecting, to an account that's one digit different from the real one.

How do criminals actually get into a real email thread to change bank details?+

Three common routes. First, a genuinely compromised mailbox, usually reached via a reused or phished password with no two-factor authentication in the way, where the criminal reads real threads for weeks before acting. Second, a lookalike domain, registering something like yourcompany-ltd.co.uk instead of yourcompany.co.uk and hoping nobody checks the sender address closely on a phone screen. Third, a spoofed From header, which SPF, DKIM and DMARC exist specifically to stop on your own domain, but does nothing to protect you from a supplier or customer whose domain isn't locked down. Any of the three ends the same way: an email that looks completely normal, in a thread that's completely real, asking for a payment to go somewhere new.

Is our business covered if we pay a fraudulent invoice by bank transfer?+

Not automatically, and this is the part most business owners haven't checked. Since October 2024, the Payment Systems Regulator's mandatory reimbursement rules cover Faster Payments and retail CHAPS fraud up to £85,000, but the in-scope customers are consumers, micro-enterprises and charities, not businesses generally. A micro-enterprise is roughly under 10 staff and under €2 million turnover or balance sheet. If your business is bigger than that, whether you get anything back is down to your bank's own goodwill and how quickly you reported it, not a legal entitlement. Ask your bank directly where your business sits against that threshold, before you need to know.

What's a safe way to verify a supplier's bank detail change?+

Never reply to the email that told you about the change, and never use a phone number pulled from that same email or its signature. Call the supplier on a number you already had on file, from a previous invoice, your own CRM, or their official website typed in manually, and ask a person you already know to confirm the new details verbally. It takes five minutes. Every case we've heard of where this habit was already in place stopped the fraud dead at that step, because the criminal doesn't have your supplier's actual phone line, only their email.

What should staff do if a message from 'the boss' asks for an urgent, unusual payment?+

Slow down and check, even if the tone is pushy or the sender claims to be travelling and hard to reach, which is a deliberate pressure tactic, not a coincidence. NCSC's own guidance on this recommends dual approval above a set threshold for any payment, so no single person, however senior the request appears, can move money out alone. If that control doesn't exist yet, a phone call to the person supposedly asking, on a number you already had, settles it in under a minute. Genuine urgency almost never means genuine secrecy.

We don't handle huge invoices. Are we actually a target?+

Yes, and arguably more of one. Criminals running this at scale don't hand-pick large companies with dedicated fraud teams; they target whoever's easiest to catch off guard, and a five-person business where one person does the books with no second sign-off is an easier target than a firm with an approvals process. UK Finance's 2026 fraud report recorded £576.4 million in authorised push payment losses across the UK in 2025, up 19% on the year before, across 248,070 cases. Most of those weren't six-figure corporate wire transfers. They were ordinary invoices, paid once, by someone who had no reason to think anything was wrong.

Can Alpha IT stop this happening to us?+

We can close off a lot of the technical routes in: locking down email accounts with two-factor authentication, setting up SPF, DKIM and DMARC so criminals can't spoof your own domain outbound, and flagging lookalike-domain risk. What we can't do is sit in your accounts payable process for you. The callback verification habit and the dual-approval threshold are decisions your team has to actually adopt and stick to. We'll help you design them properly during a health check, but nobody can install that as software.

Do we need Cyber Essentials to be protected against this?+

No, and we should be upfront that Alpha IT doesn't hold Cyber Essentials or Cyber Essentials Plus certification ourselves; our security page is a self-assessment against recognised good practice, not a certification claim. Cyber Essentials covers technical controls like firewalls, patching and access control, and a compromised mailbox with weak or no two-factor authentication is exactly the kind of gap it's designed to catch. But the callback-verification habit that actually stops a fraudulent payment going out isn't a Cyber Essentials control at all. It's a process decision, and it costs nothing to put in place.

Call usFree consultation